Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

481–490 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#481

So if I understand correctly, they want to scan all your photos, stored on your private phone, that you paid for, and they want to check if any of the hashes are the same as hashes of child porn? So... all your hashes will be uploaded to the cloud? How do you prevent them from scanning other stuff (memes, leaked documents, trump-fights-cnn-gif,... to profile the users)? Or will a huge hash database of child porn hash…

This is the big one right here. A malware will definitely be created, almost immediately, that will download files that are intentionally made to match CP - either for the purposes of extortion or just watching the world burn. I'm usually sticking my neck out in defence of more government access to private media than most on HN because of the need to stop CP, but this plan is so naive, and so incredibly irresponsible…

If you can recreate a file so it’s hash matches known CP then that file is CP my dude. The probability of just two hashes accidentally colliding is approximately: 4.3*10-60

Even if you do a content aware hash where you break the file into chunks and hash each chunk, you still wouldn’t be able to magically recreate the hash of a CP file without also producing part of the CP.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#482

Earlier quoted context omitted.

> The only difference in this is who you trust. Not really. There is a huge difference between trusting a single for-profit entity (who provides backdoor to iCloud in China) or huge number of independent people (each would like to get famous/rich for finding bugs).

Yes, because the "huge number of independent people" have never missed any serious bugs or backdoor, and they also verify every piece of equipment you use.

Nothing is ever perfectly secure. It's a question of whom you should trust for a lesser damage.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#483
I scanned the comments to find out who this person is and how they would have any inside info and found nothing. Why is this person’s claim being taken at face value? Before debating the merits of Apple scanning photos / hashes, why does anyone believe this is true?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#484

Earlier quoted context omitted.

This is a moot point unless you always verify and check all hardware and software that you use, including communications devices.

I don’t think that’s his point. The point is Apple made a laptop that did away technologies that allow PC ecosystem/choices we see today. The M1 MacBook feels like an iPhone, but sized as a laptop.

I recently bought an M1 (my first and only Apple product so far). Anecdotally, I only bought it knowing that it can execute arbitrary code without restrictions, unlike iOS. If they decide to change that then you can be sure I won't be purchasing any future models.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#485
This will be used for anti-piracy, government censorship, and targeted attacks, as always. There's no such thing as "were only scanning for CP". By creating the tool the company can be compelled to use the tool in other ways by U.S. or foreign governments. Apple already complies with anti-lgbt countries and will change their app store to suite each one of them. What happens when they're required to also scan for LGBT materials? They'll comply, because apple doesn't actually have morals.

Ontop of this, it gives apple far too much power. What happens when someone they don't like owns an iphone? They can pull an FBI and put the content onto the device, and having it then "automatically detected".

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#486
post #389

Earlier quoted context omitted.

So, it’s not that other platforms are any better! Are you sure intel, AMD, Arm or windows TPM aren’t snitching on you? Do we need to make our own silicon from ingot? There’s no technological solution to this problem, only social and legislative.

Have people already forgotten that Microsoft implemented the tech to routinely scan your cloud storage a decade ago? >The system that scans cloud drives for illegal images was created by Microsoft and Dartmouth College and donated to NCMEC. The organization creates signatures of the worst known images of child pornography, approximately 16,000 files at present. These file signatures are given to service providers who…

I'm OK with software generating signatures from cloud drive images to eliminate child porn pictures and catch pedophiles.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#487

Earlier quoted context omitted.

> If you avoid Apple, what's the point of M1? - (Potentially) programmable top notch security chip with no overhead encryption - Fanless (Air), cool running, fast processor with very low power consumption - All metal body - Top notch HiDPI screen with color accuracy. - Top notch sensors - Excellent, illuminated keyboard - Big trackpad with pressure sensitivity and taptic engine - Excellent battery life - Excellent ba…

There's no doubt that Apple makes good hardware. But you can find decent hardware elsewhere, even at lower cost and with better configurability. Everyone betting on the same horse is usually a bad strategy. By the way, here's what Linus Torvalds (the creator of Linux) thinks about using the M1: https://www.zdnet.com/article/linus-torvalds-would-like-to-u...

If we are talking about ARM64 devices specifically, the prices of the new M1 products are actually very competitive.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#488

Earlier quoted context omitted.

> If you avoid Apple, what's the point of M1? - (Potentially) programmable top notch security chip with no overhead encryption - Fanless (Air), cool running, fast processor with very low power consumption - All metal body - Top notch HiDPI screen with color accuracy. - Top notch sensors - Excellent, illuminated keyboard - Big trackpad with pressure sensitivity and taptic engine - Excellent battery life - Excellent ba…

There's no doubt that Apple makes good hardware. But you can find decent hardware elsewhere, even at lower cost and with better configurability. Everyone betting on the same horse is usually a bad strategy. By the way, here's what Linus Torvalds (the creator of Linux) thinks about using the M1: https://www.zdnet.com/article/linus-torvalds-would-like-to-u...

I’m not sure this is true? The $1000 version has absolutely ridiculous performance for it’s price class. To the point it’s nearly as good as my desktop system.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#489
post #389
post #326

Earlier quoted context omitted.

The fact that even the 'smart' people from HN can't wait for their new M1 laptop to arrive convinced me that humans are a lost cause.

So, it’s not that other platforms are any better! Are you sure intel, AMD, Arm or windows TPM aren’t snitching on you? Do we need to make our own silicon from ingot? There’s no technological solution to this problem, only social and legislative.

>windows TPM aren’t snitching on you?

The TPM FUD has really gone out of hand.

1. there's no such thing as "windows TPMs", whatever that means.

2. TPMs basically has zero access to the rest of the system. It's connected via a LPC bus, so there's no fancy DMA attacks to pull off. Over that bus the system firmware sends various hashes of the system state (eg. hash of your bootloader), but that's about it.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#490

Earlier quoted context omitted.

> My point is that they are able to switch due to the openness of the platform. And my point is that most won't, and the ones that do will still go to another platform that's controlled by another third party and they'll still need to rust that the platform is not doing things they don't like. > Millions will immediately switch given a possibility. Switch to where? To another company that could do weird things out of…

> My point is that privacy and security is not something that will be solved by federation or open source. I disagree. Here's why: > For open source and federation to be useful in that regard, you need most people to actively research and check that the tools that they use are private and secure. This is the key point. You do not need most people. You need some people. And you can always find some people who verify e…

> This is how Signal and Matrix appeared and became (relatively) famous.

And what happens when another app comes and says that "it's secure" and people start using it instead of Signal or Matrix? What happens if Signal starts requiring some payments (running servers is not free) and people move to other apps? Maybe those other apps are open source and federated, but the federation protocol is found later to have a backdoor, or some instances run data mining on the messages, or something like that. Who will be faster, the users flocking to those apps or the few number of verifiers getting to work and detecting those issues?

If you want most apps to be like Signal or Matrix, the solution is easy: push for legislation and certifications that ensure that, no matter the app, a certain level of security and privacy is enforced. It's not perfect, but it's far better than just relying on trusting that some people invest a lot of time on that research.

Post reply on HN